PkgRadar

npm · registry.npmjs.org

@jolli.ai/cli

Install Lifecycle Remote Or Exec: postinstall="node -e \"require('fs').existsSync('dist/PostInstall.js') && require('child_process').spawnSync(process.execPath,['dist/PostInstall.js'],{stdio:'inherit'})\""

Why PkgRadar flagged 0.99.2

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"require('fs').existsSync('dist/PostInstall.js') && require('child_process').spawnSync(process.execPath,['dist/PostInstall.js'],{stdio:'inherit'})\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.99.2Review102026-06-02
0.99.0Review102026-06-01
0.99.1Review102026-06-01

Block this in CI

PkgRadar gates @jolli.ai/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @jolli.ai/[email protected]